security-arsenal

Consolidate security payloads and bypass techniques into a centralized knowledge base.

Updated Apr 8, 2026
One-click install
npx skills add https://github.com/ajtazer/briyani-hunter --skill security-arsenal-ajtazer
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-arsenal
Source: https://github.com/ajtazer/briyani-hunter/tree/main/.gemini/skills/security-arsenal
Command: npx skills add https://github.com/ajtazer/briyani-hunter --skill security-arsenal-ajtazer

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Consolidates security payloads, bypass techniques, and submission rules into a centralized knowledge base to help security researchers quickly identify test vectors and avoid submitting low-quality findings.

Core Features & Use Cases

  • Payload Library: A comprehensive catalog of XSS, SSRF, SQLi, XXE, NoSQLi, SSTI, IDOR, path traversal, HTTP smuggling, WebSocket, and MFA bypass payloads.
  • Bypass Rules & Submission Guidance: Clear guidelines on when and how to submit findings to improve triage quality.
  • Pattern & GF Names: Ready-to-use gf pattern names to rapidly classify input vectors and test surfaces.

Quick Start

Query the security-arsenal to fetch relevant payloads and bypass rules for a given vulnerability type.

Frequently Asked Questions about security-arsenal

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I find XSS and SQLi payloads for penetration testing?

To find XSS and SQLi payloads for penetration testing, you can query a centralized security knowledge base that consolidates bypass techniques and payload catalogs across vulnerability classes like XSS and SQLi.

What is the best way to organize security payloads and bypass rules for VAPT workflows?

Organizing security payloads and bypass rules for VAPT workflows is best achieved by consolidating them into a centralized knowledge base loaded directly into analysis context for rapid retrieval during vulnerability testing.

Can I use gf patterns to classify input vectors during vulnerability testing?

Yes, you can use ready-to-use gf pattern names to rapidly classify input vectors and test surfaces, streamlining the identification of test vectors across various vulnerability testing scenarios.

Does this security arsenal include payloads for HTTP smuggling and WebSocket bypasses?

Yes, the security arsenal includes a comprehensive payload library that covers HTTP smuggling, WebSocket, and MFA bypasses, alongside XSS, SSRF, SQLi, XXE, NoSQLi, SSTI, IDOR, and path traversal vectors.

How do I avoid submitting low-quality findings during a pentest?

To avoid submitting low-quality findings during a pentest, apply the clear bypass rules and submission guidelines included in the knowledge base to improve triage quality before reporting vulnerabilities.

When do I need a centralized knowledge base for vulnerability testing workflows?

You need a centralized knowledge base for vulnerability testing workflows when you require on-demand access to a comprehensive catalog of security payloads, bypass techniques, and submission rules to rapidly identify test vectors.